Back to home page

DOS ain't dead

Forum index page

Log in | Register

Back to the forum
Board view  Mix view

HX updated (DOSX)

posted by Japheth Homepage, Germany (South), 08.01.2013, 08:44

> I believe that the virus-scanning software changes its scanning strategy
> when there is no valid PE header.

It doesn't really help - just makes a few warnings disappear.

> Here is a more subtle change that helps to reduce the false virus reports.
> I changed "KERNEL32.DLL" to "KERNEL32.dll" at offset 0x106D2 of the v216
> version of DKRNL32.DLL. The results at virustotal.com dropped to 8/43. All
> of the generic errors disappeared, and only the Virumonde trojan reports
> remained.

I'll try.

---
MS-DOS forever!

 

Complete thread:

Back to the forum
Board view  Mix view
22049 Postings in 2034 Threads, 396 registered users, 196 users online (0 registered, 196 guests)
DOS ain't dead | Admin contact
RSS Feed
powered by my little forum